Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20221130-01-C7F72FFB-EN
HistoryNov 23, 2022 - 12:00 a.m.

Security Advisory - Insufficient Authentication Vulnerability in some Huawei Band Products

2022-11-2300:00:00
Huawei Technologies
www.huawei.com
11
security
advisory
huawei
band
products
insufficient
authentication
vulnerability
exploit
spoof
connect
cve

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

30.5%

There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band. (Vulnerability ID: HWPSIRT-2022-85585)

This vulnerability has been assigned a (CVE) ID: CVE-2022-41579

Affected configurations

Vulners
Node
huaweihota-fara-b19Match11.1.2.40-fullpackage-ota

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

30.5%

Related for HUAWEI-SA-20221130-01-C7F72FFB-EN